Tag
medium
advisory
Network Connection via Compiled HTML File
2 rules 3 TTPsThis rule detects network connections initiated by hh.exe, the HTML Help executable, which may indicate the execution of malicious code embedded in compiled HTML files (.chm) to deliver malicious payloads, bypass security controls, and gain initial access via social engineering.
HTML Help
execution
defense-evasion
command-and-control
malicious-file
html-help
2r
3t
high
advisory
HTML Help Executable Spawning Child Processes
2 rules 1 TTPThe execution of hh.exe (HTML Help) spawning a child process indicates the use of a Compiled HTML Help (CHM) file to execute potentially malicious Windows script code.
Microsoft Windows
html-help
chm
lolbas
process-creation
2r
1t